Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I used to have an ISP that would inject ads into HTTP sites. Every site needs HTTPS.


Or, your ISP does not deserve to exist.


True but you can’t build distributed systems that rely on every single actor being a good one. Hence encryption, the police, etc.


The police is a good example, instead of reinventing basal language, we instead have a body of people who enforce the law.

It’s not like ISPs are unknown entities.


What about governments? In my country they perform MITM attacks against unencrypted HTTP, while the best they can do with HTTPS is to block the site. I'd much prefer everyone enforcing HTTPS at all times.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: